Hi Rengar,
The policyname field in the detailed information about the session table indicates the name of the security policy matched by the packet. If this field is displayed as ---, the packet corresponding to the session is in the policy pending state or does not need to be checked by the security policy.
Policy undetermined indicates that the application or URL category matching condition is configured in the policy, the firewall is identifying the application or URL category of the packet, and the matched security policy is not determined. After application identification or URL category query is complete, if the packet is permitted by the security policy to refresh the session, this field displays the name of the matched security policy.
If security policy check is not required, for example, access management is enabled on an interface, some packets destined for the device will not be checked by security policies. The packet matches the authentication policy whose authentication action is Portal authentication. When the user sends an HTTP/HTTPS request to the web server, the first SYN packet is not controlled by the security policy.
I hope it helps!